Skip to content

customize
Current Activity Calendar
Left Arrow
October 2007
Right Arrow
Su M Tu W Th F Sa
  1 2 3 4 5 6
7 8 9 10 11 12 13
14 15 16 17 18 19 20
21 22 23 24 25 26 27
28 29 30 31
Please click on a date above to see current activity for that day.

  • Latest Current Activity
  • October 02, 2007 - Current Activity

    This is an archived copy of current activity, if you would like to see the most recent version, please click here.

    October 2Google's Gmail XSRF Vulnerability
    September 27Apple Releases Update for iPhone
    September 27CA BrightStor Hierarchical Storage Manager Vulnerabilities
    September 27Cisco Products Loopback Vulnerability
    September 24CA ARCserve Backup for Laptops and Desktops contains multiple vulnerabilities
    September 24Google Search Appliance Vulnerability
    September 21Reports of Multiple Product PDF Rendering Vulnerability



    Google's Gmail XSRF Vulnerability

    added October 2, 2007 at 09:10 am | updated October 2, 2007 at 09:11 am

    US-CERT is aware of a publicly reported cross-site request forgery vulnerability in Google's Gmail. A cross-site request forgery vulnerability may allow a request from an attacker to be interpreted as originating from an authenticated user.  Public reports indicate that this vulnerability may allow an attacker to create arbitrary filters for a user's Gmail account.  

    More information regarding this vulnerability can be found in Vulnerability Note VU#571584.


    Apple Releases Update for iPhone

    added September 27, 2007 at 03:29 pm

    Apple has released an update to address several vulnerabilities in the iPhone. These vulnerabilities may allow an attacker to execute arbitrary code or commands, cause a denial-of-service condition, or conduct cross-site scripting attacks on an affected device.

    More information about these vulnerabilities and the iPhone v1.1.1 update can be found in the Apple update advisory.

    US-CERT strongly encourages users to review the advisory and follow best-practice security policies to determine what updates should be applied.


    CA BrightStor Hierarchical Storage Manager Vulnerabilities

    added September 27, 2007 at 09:55 am

    US-CERT is aware of several vulnerabilities that affect the CA BrightStor Hierarchical Storage Manager version r11.5.  These vulnerabilities may allow an attacker to execute arbitrary code or gain control of the system.

    More information regarding these vulnerabilities can be found in the CA BrightStor Hierarchical Storage Manager CsAgent Security Notice.

    US-CERT recommends that users upgrade to the latest version to help mitigate the security risks.


    Cisco Products Loopback Vulnerability

    added September 27, 2007 at 09:25 am

    Cisco has released a Security Response regarding a vulnerability in the way that Cisco Catalyst 6500 and Cisco 7600 series devices use addresses from the loopback range. Cisco reports that an attacker can exploit this to bypass access control lists.

    US-CERT encourages users to apply the workarounds and software updates as listed in the Cisco Security Response.

    US-CERT will provide additional information as it becomes available.


    CA ARCserve Backup for Laptops and Desktops contains multiple vulnerabilities

    added September 24, 2007 at 03:02 pm

    US-CERT is aware of several vulnerabilities that affect the CA ARCserve Backup for Laptops and Desktops product. These vulnerabilities may allow an attacker to execute arbitrary code, bypass authentication, or cause a denial-of-service condition.

    More information regarding these vulnerabilities and which applications are affected can be found in the CA Security Advisor "CA ARCserve Backup for Laptops and Desktops Multiple Server Vulnerabilities" document.

    US-CERT recommends that users upgrade to the latest versions to help mitigate the security risks.



    Google Search Appliance Vulnerability

    added September 24, 2007 at 12:28 pm

    US-CERT is aware of a publicly reported cross-site scripting (XSS) vulnerability in Google's search appliance. Cross-site scripting vulnerabilities may allow a remote, unauthenticated attacker to inject malicious script into a web page.

    US-CERT encourages users to follow best-practice security policies as described in the Securing Your Web Browser document.

    US-CERT will provide additional information as it becomes available.


    Reports of Multiple Product PDF Rendering Vulnerability

    added September 21, 2007 at 03:24 pm

    US-CERT is aware of public reports of a vulnerability that may affect Adobe Acrobat, Adobe Acrobat Reader, and Foxit Reader. Few details are currently available, but it is claimed that an attacker may be able to execute arbitrary code or commands on an affected system by enticing a user to open a specially crafted PDF document.

    Until a security fix becomes available, US-CERT recommends users take the following actions that may help mitigate the security risk:

    • Do not open unsolicited or untrusted PDF files.
    • Disable the displaying of PDF documents in the web browser as described in the "Solution" section of Vulnerability Note VU#815960.
    • Utilize available PDF rendering services as policies permit.
    US-CERT will continue to investigate this issue and provide more information as it becomes available.